caldera records
82 published records for vendor caldera.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 1.2%
- Pre-auth RCE
- 13
- With a fix record
- 1.2%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
82 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2000-0917Weaponized | Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.caldera · openlinux ebuilder | Critical10.0 | — | 78.7% | Dec 19, 2000 |
52Plan | CVE-1999-0043No exploit | Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.isc · inn · CWE-78 | Critical9.8 | — | 44.6% | Dec 4, 1996 |
52Plan | CVE-1999-0368Proof of concept | Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a.proftpd project · proftpd | Critical10.0 | — | 39.8% | Feb 9, 1999 |
49Plan | CVE-1999-0009Proof of concept | Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.data general · dg ux | Critical10.0 | — | 29.0% | Apr 8, 1998 |
48Plan | CVE-1999-0002Proof of concept | Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.bsdi · bsd os · CWE-119 | Critical10.0 | — | 27.9% | Oct 12, 1998 |
47Plan | CVE-2002-0679No exploit | Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrcaldera · unixware | Critical10.0 | — | 23.3% | Sep 5, 2002 |
45Plan | CVE-2000-0491Proof of concept | Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a degnome · gdm | Critical10.0 | — | 17.8% | May 24, 2000 |
45Plan | CVE-2000-0844Proof of concept | Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackecaldera · openlinux ebuilder · CWE-264 | Critical10.0 | — | 15.6% | Nov 14, 2000 |
44Plan | CVE-1999-0042Proof of concept | Buffer overflow in University of Washington's implementation of IMAP and POP servers.university of washington · imap | Critical10.0 | — | 12.7% | Apr 7, 1997 |
43Plan | CVE-1999-0879Proof of concept | Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.bsdi · bsd os | Critical10.0 | — | 9.7% | Oct 1, 1999 |
42Plan | CVE-2001-0181No exploit | Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrarcaldera · openlinux desktop | Critical10.0 | — | 5.2% | Mar 26, 2001 |
41Plan | CVE-2000-0370No exploit | The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail caldera · openlinux | Critical10.0 | — | 4.8% | Jan 29, 1999 |
41Plan | CVE-2002-0311Proof of concept | Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell mcaldera · unixware | Critical10.0 | — | 4.5% | May 31, 2002 |
41Plan | CVE-2014-2935No exploit | costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute arbitrary commands via shell metacharactercaldera · caldera · CWE-78 | Critical10.0 | — | 4.4% | May 8, 2014 |
41Plan | CVE-2000-0374No exploit | The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, whcaldera · openlinux | Critical10.0 | — | 4.3% | Aug 22, 1999 |
41Plan | CVE-1999-0047No exploit | MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.eric allman · sendmail | Critical10.0 | — | 3.1% | Jan 28, 1997 |
41Plan | CVE-2001-1359No exploit | Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which acaldera · volution | Critical10.0 | — | 2.8% | Jun 8, 2001 |
41Plan | CVE-2001-0850No exploit | A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allcaldera · openlinux | Critical10.0 | — | 2.3% | Dec 6, 2001 |
41Plan | CVE-2002-0988No exploit | Buffer overflow in X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1, possibly related to XBM/xkbcomp capabilities.caldera · unixware | Critical10.0 | — | 2.0% | Sep 24, 2002 |
32Monitor | CVE-2002-0677No exploit | CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain pricaldera · unixware | High7.5 | — | 6.6% | Jul 23, 2002 |
31Monitor | CVE-2002-0678No exploit | CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file ucaldera · unixware | High7.2 | — | 9.4% | Jul 23, 2002 |
31Monitor | CVE-2002-0885No exploit | Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIXcaldera · unixware | High7.5 | — | 3.3% | Oct 4, 2002 |
31Monitor | CVE-2001-0869No exploit | Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow rcaldera · openlinux workstation | High7.5 | — | 3.0% | Dec 21, 2001 |
31Monitor | CVE-2002-0884No exploit | Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Open UNIX, and possibly other operating syscaldera · unixware | High7.5 | — | 2.8% | Oct 4, 2002 |
31Monitor | CVE-1999-0439No exploit | Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configprocmail · procmail | High7.5 | — | 2.5% | Apr 5, 1999 |
- CVE-2000-091764This week
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
CriticalCVSS 10.0WeaponizedEPSS 79%caldera · openlinux ebuilderDec 19, 2000
- CVE-1999-004352Plan
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
CriticalCVSS 9.8No exploitEPSS 45%isc · innDec 4, 1996
- CVE-1999-036852Plan
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a.
CriticalCVSS 10.0Proof of conceptEPSS 40%proftpd project · proftpdFeb 9, 1999
- CVE-1999-000949Plan
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
CriticalCVSS 10.0Proof of conceptEPSS 29%data general · dg uxApr 8, 1998
- CVE-1999-000248Plan
Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.
CriticalCVSS 10.0Proof of conceptEPSS 28%bsdi · bsd osOct 12, 1998
- CVE-2002-067947Plan
Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitr
CriticalCVSS 10.0No exploitEPSS 23%caldera · unixwareSep 5, 2002
- CVE-2000-049145Plan
Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a de
CriticalCVSS 10.0Proof of conceptEPSS 18%gnome · gdmMay 24, 2000
- CVE-2000-084445Plan
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attacke
CriticalCVSS 10.0Proof of conceptEPSS 16%caldera · openlinux ebuilderNov 14, 2000
- CVE-1999-004244Plan
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
CriticalCVSS 10.0Proof of conceptEPSS 13%university of washington · imapApr 7, 1997
- CVE-1999-087943Plan
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.
CriticalCVSS 10.0Proof of conceptEPSS 10%bsdi · bsd osOct 1, 1999
- CVE-2001-018142Plan
Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrar
CriticalCVSS 10.0No exploitEPSS 5%caldera · openlinux desktopMar 26, 2001
- CVE-2000-037041Plan
The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail
CriticalCVSS 10.0No exploitEPSS 5%caldera · openlinuxJan 29, 1999
- CVE-2002-031141Plan
Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell m
CriticalCVSS 10.0Proof of conceptEPSS 5%caldera · unixwareMay 31, 2002
- CVE-2014-293541Plan
costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute arbitrary commands via shell metacharacter
CriticalCVSS 10.0No exploitEPSS 4%caldera · calderaMay 8, 2014
- CVE-2000-037441Plan
The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, wh
CriticalCVSS 10.0No exploitEPSS 4%caldera · openlinuxAug 22, 1999
- CVE-1999-004741Plan
MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.
CriticalCVSS 10.0No exploitEPSS 3%eric allman · sendmailJan 28, 1997
- CVE-2001-135941Plan
Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which a
CriticalCVSS 10.0No exploitEPSS 3%caldera · volutionJun 8, 2001
- CVE-2001-085041Plan
A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could all
CriticalCVSS 10.0No exploitEPSS 2%caldera · openlinuxDec 6, 2001
- CVE-2002-098841Plan
Buffer overflow in X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1, possibly related to XBM/xkbcomp capabilities.
CriticalCVSS 10.0No exploitEPSS 2%caldera · unixwareSep 24, 2002
- CVE-2002-067732Monitor
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain pri
HighCVSS 7.5No exploitEPSS 7%caldera · unixwareJul 23, 2002
- CVE-2002-067831Monitor
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file u
HighCVSS 7.2No exploitEPSS 9%caldera · unixwareJul 23, 2002
- CVE-2002-088531Monitor
Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX
HighCVSS 7.5No exploitEPSS 3%caldera · unixwareOct 4, 2002
- CVE-2001-086931Monitor
Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow r
HighCVSS 7.5No exploitEPSS 3%caldera · openlinux workstationDec 21, 2001
- CVE-2002-088431Monitor
Multiple format string vulnerabilities in in.rarpd (ARP server) on Solaris, Caldera UnixWare and Open UNIX, and possibly other operating sys
HighCVSS 7.5No exploitEPSS 3%caldera · unixwareOct 4, 2002
- CVE-1999-043931Monitor
Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc config
HighCVSS 7.5No exploitEPSS 3%procmail · procmailApr 5, 1999